CVE-2023-26136
published 2023-07-01CVE-2023-26136: Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.54%
83.2th percentile
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-tough-cookie | < node-tough-cookie 4.0.0-2+deb12u1 (bookworm) | node-tough-cookie 4.0.0-2+deb12u1 (bookworm) |
| msrc | azl3_python-tensorboard_2.16.2-6_on_azure_linux_3.0 | — | — |
| salesforce | tough-cookie | < 4.1.3 | 4.1.3 |
| salesforce | tough-cookie | >= 0 < 4.1.3 | 4.1.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Subnet Solutions PowerSYSTEM Center
cisa_ics·2024-07-18·CVSS 6.5
[MEDIUM] Subnet Solutions PowerSYSTEM Center
ICS Advisory
##
Subnet Solutions PowerSYSTEM Center
Release DateJuly 18, 2024
Alert CodeICSA-24-200-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Subnet Solutions Inc.
- Equipment: Subnet PowerSYSTEM Center
- Vulnerability: Prototype Pollution
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an authenticated attacker to elevate permissions.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Subnet PowerSYSTEM Center are affected:
- PowerSYSTEM Center 2020: Update 20 and prior
## 3.2 Vulnerability Overview
## 3.2.1 IMPROPERLY CONTROLLED MOD
Microsoft
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises f
vendor_msrc·2023-07-11·CVSS 9.8
CVE-2023-26136 [MEDIUM] CWE-1321 Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises f
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to a
Red Hat
tough-cookie: prototype pollution in cookie memstore
vendor_redhat·2023-07-01·CVSS 6.5
CVE-2023-26136 [MEDIUM] CWE-1321 tough-cookie: prototype pollution in cookie memstore
tough-cookie: prototype pollution in cookie memstore
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
A flaw was found in the tough-cookie package which allows Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Package: tough-cookie (Cryostat 2) - Not affected
Package: openshift-logging/kibana6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: mta/mta-ui-rhel8 (Migration Toolkit for Applications 6) - Will not fix
Package: tough-co
Debian
CVE-2023-26136: node-tough-cookie - Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Po...
vendor_debian·2023·CVSS 6.5
CVE-2023-26136 [MEDIUM] CVE-2023-26136: node-tough-cookie - Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Po...
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Scope: local
bookworm: resolved (fixed in 4.0.0-2+deb12u1)
bullseye: resolved (fixed in 4.0.0-2+deb11u1)
forky: resolved (fixed in 4.1.3+~4.0.2-1)
sid: resolved (fixed in 4.1.3+~4.0.2-1)
trixie: resolved (fixed in 4.1.3+~4.0.2-1)
GHSA
tough-cookie Prototype Pollution vulnerability
ghsa·2023-07-01
CVE-2023-26136 [MEDIUM] CWE-1321 tough-cookie Prototype Pollution vulnerability
tough-cookie Prototype Pollution vulnerability
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in `rejectPublicSuffixes=false` mode. This issue arises from the manner in which the objects are initialized.
OSV
tough-cookie Prototype Pollution vulnerability
osv·2023-07-01
CVE-2023-26136 [MEDIUM] tough-cookie Prototype Pollution vulnerability
tough-cookie Prototype Pollution vulnerability
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in `rejectPublicSuffixes=false` mode. This issue arises from the manner in which the objects are initialized.
OSV
CVE-2023-26136: Versions of the package tough-cookie before 4
osv·2023-07-01·CVSS 9.8
CVE-2023-26136 [CRITICAL] CVE-2023-26136: Versions of the package tough-cookie before 4
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
No detection rules found.
No public exploits indexed.
https://github.com/salesforce/tough-cookie/commit/12d474791bb856004e858fdb1c47b7608d09cf6ehttps://github.com/salesforce/tough-cookie/issues/282https://github.com/salesforce/tough-cookie/releases/tag/v4.1.3https://lists.debian.org/debian-lts-announce/2023/07/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2/https://lists.fedoraproject.org/archives/list/[email protected]/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ/https://security.netapp.com/advisory/ntap-20240621-0006/https://security.snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873https://github.com/salesforce/tough-cookie/commit/12d474791bb856004e858fdb1c47b7608d09cf6ehttps://github.com/salesforce/tough-cookie/issues/282https://github.com/salesforce/tough-cookie/releases/tag/v4.1.3https://lists.debian.org/debian-lts-announce/2023/07/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2/https://lists.fedoraproject.org/archives/list/[email protected]/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ/https://security.netapp.com/advisory/ntap-20240621-0006/https://security.snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873
2023-07-01
Published